[Bug 296521] bin/pfctl: pf's netlink conversion blocks non-VNET jails from using pfctl (no allow.pf / RTNL_F_ALLOW_NONVNET_JAIL equivalent)
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sun, 05 Jul 2026 08:30:27 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296521
Marek Zarychta <zarychtam@plan-b.pwste.edu.pl> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |zarychtam@plan-b.pwste.edu.
| |pl
--- Comment #1 from Marek Zarychta <zarychtam@plan-b.pwste.edu.pl> ---
Is this an actual bug, or simply a stricter implementation?
For non-VNET jails, PF is expected to be managed from the host. As far as I
understand, that's the recommended and documented deployment model.
On the other hand, if this used to work, perhaps it should still be allowed for
compatibility reasons.
What is the intended behaviour for the other firewalls? In particular, are IPFW
and IPF expected to be manageable from non-VNET jails, or are they managed
exclusively from the host?
--
You are receiving this mail because:
You are the assignee for the bug.